AI AI Toolkit
AI Newsai-products

Modal 发布 VM Sandboxes、Modal Clusters 等多项 Runtime 产品更新

Modal 官方工程博客(RSS)2026-10-01T00:00:00.000Z

Key Highlights

At its first Runtime conference, Modal announced several product updates centered on giving AI agents a more complete execution environment: VM Sandboxes provide a full Linux virtual machine, Modal Clusters let teams run their own always-on compute pools, and Sandbox Endpoints turn sandboxes into callable services. Together they move Modal from a function runner toward agent infrastructure.

What Happened

Over the past year Modal has shifted from a "run functions" platform to a "give agents a computer" platform. VM Sandboxes are already in production at customers like Linear and Legora, running real workloads that need Docker, FUSE, and kernel capabilities rather than merely restricted containers. That shift matters because agents increasingly need to do things containers cannot, like mount filesystems or use kernel features.

Technical Details

VM Sandboxes are enabled by setting runtime="vm" to get a full Linux VM, reusing the original Sandbox calling interface, modal.Image, and sub-second cold starts. Modal Clusters let enterprises keep GPU and CPU pools resident to avoid repeated cold starts, while Sandbox Endpoints expose a sandbox as an HTTP endpoint for easy embedding into existing systems. The consistency of the interface means existing code keeps working when you switch to a VM.

Comparison with Competitors

E2B, Fly.io, and others are also building agent execution environments, but Modal's difference is fusing cloud-native scheduling, images, and billing with "a real machine for the agent" in one place, so teams already on Modal face almost no migration cost. The integrated billing and scheduling remove a whole class of operational glue that competitors leave to the user.

Industry Impact and Use Cases

Agents that write code, drive browsers, process data, or call kernel tools all need a trustworthy yet isolated runtime surface. Modal's updates move the "agent's computer" from a toy into production-grade infrastructure that security and finance teams can actually approve. That approval step is often the real blocker for shipping agents, not the model.

Further Analysis

Put simply, whether an agent can actually do work depends half on whether it has a reliable machine. Containers are too restricted and bare cloud is too heavy, so VM Sandboxes aim for the middle: full system calls with Serverless elasticity. For teams building agent products, this kind of execution layer will gradually replace self-managed Kubernetes as the default substrate. You just write the logic and let the platform handle the machine, the patching, and the scaling.

Data and Methodology

Modal's named customers, Linear and Legora, are case endorsements rather than independent benchmarks. The "sub-second cold start" for VM Sandboxes is stable only under a resident Cluster; spinning up a VM on demand can still carry start-up overhead, so citations should distinguish the two modes instead of blending them.

Risks and Limitations

Giving an agent a whole VM raises capability and also expands the attack surface: malicious code can touch the kernel and mount filesystems. Isolation depends on Sidecars and sandbox policy, and a wrong configuration leaks. On cost, a resident Cluster suits steady load, while sporadic tasks are cheaper on demand.

Advice for Engineering Teams

First inventory which agents truly need full system calls before deciding between VM and container. Confine untrusted code inside the Sidecar trust boundary, and wire sandbox lifecycles into your orchestration so machines do not sit idle and burn money while nothing runs.

Market Position

Modal wants to turn "the agent's computer" into a cloud-native product rather than something users self-manage on Kubernetes. Its rivals are not only E2B but also the container services of cloud vendors. Modal's chips are developer experience and unified billing, betting on the execution-layer demand that an agent-volume explosion will bring.

Extended Observation

The execution layer becomes a new battleground in AI infrastructure. Whoever gives full system capability while keeping elasticity and isolation wins the "cloud" entry point of the agent era. The maturity of such platforms directly decides how many real jobs agents can take on, so it is worth watching as a leading indicator.

Takeaway

Put simply, for an agent to do real work it needs a reliable machine. VM Sandboxes fuse a full system with elasticity, which is the pragmatic answer for the agent-era execution layer and deserves a place on your shortlist when you evaluate where agents should actually run.